Medical Device Penetration Tester
Run deep-dive penetration tests across medical devices, firmware, mobile apps, APIs, and cloud components, then translate findings into regulator-ready evidence.
- Reports to
- CTO and delivery team lead
- Status
- Full-time
- Location
- Remote (United States), up to 40% client travel as required
- Compensation
- Competitive, commensurate with experience, paid every two weeks, plus benefits including health, dental, vision, 401(k), and an educational allowance
- Equipment
- Bring your own laptop and testing setup, and we cover the project-specific hardware and lab gear the work needs
About the role
Blue Goat Cyber is expanding, and we are looking for a highly skilled Medical Device Penetration Tester who takes pride in uncovering vulnerabilities that protect patient safety and advance secure innovation in healthcare technology. In this role you will execute deep-dive penetration tests across medical devices and their supporting systems, then translate complex findings into clear, actionable guidance aligned with FDA cybersecurity expectations.
Our mission is to secure medical innovation by delivering technical depth, clinical-risk awareness, and regulatory-aligned cybersecurity guidance. This role helps our clients ship devices that are secure, compliant, and safe for patients without slowing innovation.
This role requires strong technical proficiency, excellent communication, and an ownership-driven work style. You must be available for weekly team meetings, including client meetings.
You are a fit if
You excel in execution and ownership
- You work independently and take full ownership of your deliverables.
- You manage time exceptionally well and consistently meet deadlines.
- You stay ahead of your workload and proactively flag risks or blockers early.
- You follow through and close loops, so stakeholders never wonder where things stand.
You produce accurate, polished technical work
- You deliver clean, well-structured, client-ready reports that require minimal editing.
- Your documentation is meticulous, accurate, and repeatable.
- You never sacrifice rigor for speed.
- You validate assumptions and show your work when testing or documenting vulnerabilities.
You communicate like a professional
- You communicate constraints, delays, and questions proactively.
- You respond promptly to messages and client inquiries.
- You ask thoughtful questions early to ensure alignment.
- You are open to feedback and use it to refine and elevate your work.
You think and solve like a security leader
- You are resourceful and find solutions in complex environments.
- You adapt quickly to changing scope or technical challenges.
- You stay current on threat trends, tooling, and FDA cybersecurity direction.
- You take initiative, improve processes, and share knowledge generously.
You thrive in collaborative, remote-first work
- You enjoy working with high-performing peers and supporting team success.
- You build trust through transparency, responsiveness, and consistent delivery.
- You uphold the company's reputation with professionalism and excellence.
- You bring a positive, mature, problem-solving mindset to your work every day.
What you will own
Security testing and vulnerability research
- Conduct penetration testing across medical devices, software platforms, firmware, mobile apps, APIs, cloud components, and supporting systems.
- Perform manual exploitation and advanced testing methods, not just scanner output.
- Maintain thorough notes, artifacts, and reproducible steps supporting each finding.
Threat modeling and risk assessment
- Perform structured threat modeling using STRIDE, data flow diagram analysis, and attack surface mapping.
- Evaluate clinical and patient-safety risk impacts for vulnerabilities.
- Support cybersecurity risk assessments aligned with FDA secure development expectations.
Reporting and evidence delivery
- Write clear, technical, logically structured penetration test reports.
- Document proof-of-concept evidence, risk ratings, and remediation paths aligned to regulatory needs.
- Support evidence packages that feed into FDA submissions and secure SDLC documentation.
Client communication and accountability
- Participate in scoping, kickoff, update, and debrief calls.
- Communicate blockers, clarifying questions, and status updates proactively.
- Work collaboratively with the delivery team to guide remediation.
- Update progress in Asana and maintain full transparency on timelines.
- Book and manage travel when required for onsite testing.
Required skills and experience
- Experience in medical device security or IoT for regulated industries.
- Familiarity with regulatory standards: FDA cybersecurity guidance, IEC 81001-5-1, IEC 62304, and NIST SP 800-115.
- Relevant certifications such as OSCP, OSWE, or CISSP.
- Strong written communication; able to convert technical findings into client-ready deliverables.
- Experience working remotely with minimal supervision, managing your own deliverables and deadlines.
Preferred experience
- Hands-on hardware and firmware work: JTAG and UART access, flash extraction, and binary analysis.
- Radio and protocol testing across Bluetooth Low Energy, Wi-Fi, NFC, and proprietary RF.
- Experience testing devices that were later submitted to the FDA, and familiarity with how findings land in a submission.
- Working knowledge of AAMI TIR57, ANSI/AAMI SW96, and threat modeling with STRIDE.
- Clinical or hospital environment exposure, including how devices behave in real care workflows.
Your first 90 days
What success looks like early on, so you know what you are walking into.
- 1
First 30 days
- Get set up in our lab and reporting workflow and review recent engagements end to end.
- Pair on an active test so you see how findings become submission evidence.
- Learn our risk rating approach and how clinical impact changes severity.
- 2
Days 30 to 60
- Lead your own engagement from scoping through the debrief call.
- Produce a client-ready report with reproducible steps and proof-of-concept evidence.
- Run structured threat modeling on a device and defend the attack surface you mapped.
- 3
Days 60 to 90
- Carry concurrent engagements and manage your own schedule and travel.
- Guide client remediation conversations without a delivery lead in the room.
- Contribute tooling, tradecraft, or methodology improvements back to the team.
Tools we use
- Google Workspace
- Slack
- Asana
- FOSSA
- Snyk
- Burp Suite
- Tenable Nessus
- reconFTW
- Hak5 IoT tools
- HackRF One
- Linux (experienced)
About Blue Goat Cyber
Blue Goat Cyber is a medical device cybersecurity company dedicated to protecting patient lives by securing the technologies that power modern healthcare. We support medical device manufacturers as they build, test, and launch secure devices that meet FDA expectations and operate safely in the real world.
We are a remote, high-trust, high-ownership team that values clear communication, rigorous thinking, proactive problem solving, continuous learning, and attention to critical details. We expect every team member to own their work, communicate clearly, and support the mission without ego.
Before you apply
The terms every person here works under. Read them now rather than at offer stage, along with our core values and the honest list of who this is not for.
Rules of engagement
- You test only what is named in a signed, written scope, within the authorized window, using the authorized methods.
- No testing of client systems, assets, or third parties outside that written authorization, ever, including casual reconnaissance before a contract exists.
- Stop and escalate immediately on anything that could affect patient safety, clinical availability, or production data.
- Findings, exploits, and proof-of-concept code belong to the engagement. They are not published, reused across clients, or added to a personal portfolio.
Loaner devices and home lab
- Client devices are shipped to you under chain of custody. You log receipt, keep them physically secured and separated from personal equipment, and return them in documented condition.
- Device data, firmware images, and extracted artifacts are stored encrypted and destroyed on our schedule at engagement close.
- Your test network is isolated from your household network and from any other client's work.
- We supply project-specific hardware and lab gear; your general workstation and setup are yours, with the home office allowance toward it.
Engagement conduct
- Work product created for an engagement belongs to the client or to Blue Goat Cyber as the client agreement specifies.
- Disclose any outside work that could create a conflict of interest with a client of ours before taking it on.
Work authorization
- You must be authorized to work in the United States. We do not sponsor visas for these roles.
- All roles are performed from within the United States.
Confidentiality and NDA
- You will sign a mutual nondisclosure agreement before you see any client material, and client-specific NDAs where a client requires one.
- You will see unreleased device designs, firmware, source code, vulnerabilities, and submission content. None of it is yours to discuss, publish, screenshot, or reference, during or after the engagement.
- Client material stays in company systems. No personal cloud storage, personal email, personal repositories, or unvetted AI tools.
- Anything we publish that draws on client work is anonymized and cleared with the client first.
How we expect you to use AI
- Use AI every day if it helps, on the company ChatGPT and Claude accounts we provide, and keep client material inside them: firmware, source code, submission documents, findings, and client names never go anywhere else.
- You own the accuracy of anything you send out, because models get recognition numbers, clause references, and test conclusions wrong in ways that read perfectly well. The full policy is in the careers FAQ.
Security and background
- Offers are contingent on a background check and on reference checks.
- You will use company-required security controls on any device that touches client data, including full-disk encryption, screen lock, and our password manager and multi-factor authentication.
- Report a suspected compromise or data exposure immediately. We treat honest, fast reporting as the right behavior, not a fault.
- Some client engagements require additional screening or training before you can be assigned.
Equal opportunity
- Blue Goat Cyber is an equal opportunity employer. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic.
- If you need an accommodation at any point in the hiring process, tell us and we will arrange it.
Apply
Send your resume, any links to your work, and a short note about why this role fits. It takes a few minutes and a real person on our team reads every application.
If you do not hear back within two weeks, we have decided not to move forward for now. We keep applications on file for future openings.
